Current preview note · updated 27 August 2026
Privacy and sponsor review
CrownTheMap is a FluxonLab microproject. Public country pages use aggregate vote facts. Sponsor review, when its intake gate is open, separates the public sponsor profile from private business details.
Sponsor application data
The public profile contains the chosen country, sponsor name, optional short line, and exact destination. Private review data contains the contact email, registered legal name, business registration reference, establishment and billing facts, business-purchase confirmation, and VAT ID where required.
Private details are used only for eligibility review, required communication, and later billing if the separately gated checkout is enabled. They are not placed in public output or behavioral analytics.
Security and access
- Application and approval pages are private, no-store, and excluded from indexing.
- Approval links use an opaque code in the URL fragment; the database stores only a one-way hash and a random derivation nonce.
- Destination pages are never fetched or previewed by CrownTheMap.
- Founder review actions create an append-only audit record without copying private application fields into that audit.
Voting data and final-result retention
The no-account voting design uses a random round-scoped browser token and stores keyed hashes rather than the token itself. It cannot promise one verified human per vote. Vote-key material is not eligible for deletion until exactly 720 hours after finalization, and the aggregate immutable final result remains after that maintenance runs.
Current launch gate
Real public intake remains disabled until sponsor-data retention, processor disclosures, controller and rights-request details, seller details, legal terms, and provider configuration are approved. No live payment route is enabled. Current sponsor rules are in the Content Policy, and the non-commerce boundary is in the Sponsored Crown terms.